GHSA-2m8v-j782-fhvrHighCVSS 7.5

Socket.IO: Zero-attachment Memory Exhaustion

Published
August 3, 2026
Last Modified
August 3, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.

Patches

| Version range | Used by | Fixed version | |------------------|--------------------------------------------|---------------| | >=4.0.0 <4.2.7 | [email protected] and [email protected] | 4.2.7 | | >=3.4.0 <3.4.5 | [email protected] | 3.4.5 | | <3.3.6 | [email protected] | 3.3.6 |

Workarounds

There is no known workaround except upgrading to a safe version.

For more information

If you have any questions or comments about this advisory:

  • Open a discussion here

🎯 Affected products3

  • npm/socket.io-parser:>= 4.0.0, < 4.2.7
  • npm/socket.io-parser:>= 3.4.0, < 3.4.5
  • npm/socket.io-parser:< 3.3.6

🔗 References (5)